Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

Traffic dropped only in clean-up rule??

Hi Guys.
I’m running tests on URL Filtering with a Check Point cluster running R81.20 with Jumbo Hotfix Take 99.
HTTPS Inspection is not enabled.

There is a rule inside an inline layer that blocks traffic categorized as Sex/pornography

behavior:

  • When the cleanup rule of the inline layer is set to Drop, the site is blocked correctly

  • When the cleanup is set to Accept, the site loads successfully 

  • The site in question is correctly categorized as Sex/pornography

  • QUIC traffic is blocked via a separate rule

Why is this site being blocked only when the inline layer's cleanup rule is set to Drop, even though it doesn’t match the rule above that should block it based on its category?
Thanks a lot

0 Kudos
37 Replies
PhoneBoy
Admin
Admin

QUIC and HTTP/3 support were major features of R82.
No plans to backport to earlier releases.

0 Kudos
the_rock
MVP Gold
MVP Gold

TAC guy told me the same recently...definitely major features of R82.

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Indeed but with HTTPS/QUIC inspection off i'm not sure it explains the observations here.

CCSM R77/R80/ELITE
0 Kudos
RemoteUser
Advisor

Hi @Chris_Atkinson 

If you try yourself to see the behavior of url block filtering on some sites, in R82 and R81.20, you will notice the difference, (without https inspection enabled)

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

I'm happy that your satisfied that R82 is the answer but without inspection enabled im not seeing any documentation that supports this should be the case, hope it is clear.

CCSM R77/R80/ELITE
PhoneBoy
Admin
Admin

I imagine adding support for HTTP/3 and QUIC also included improvements to parsing the relevant traffic for HTTPS Categorization purposes.
Which might explain @RemoteUser‘s experience (even if such improvements aren’t explicitly documented).

0 Kudos
RemoteUser
Advisor

TLS version1.2 i see

0 Kudos
the_rock
MVP Gold
MVP Gold

Part of this could be ssl indpection being off, though for this issue, it just wont present block page.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events